VDB

CVE-2004-1319

CVE-2004-1319 PUBLISHED CVSS 5 MEDIUM

The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.

EPSS 31.30% · 96.9th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
31.30%
96.9th percentile

Affected Products

VendorProductVersions
microsoftwindows_98
n/an/a*
nortelmobile_voice_client_2050
microsoftwindows_98se
norteloptivity_telephony_manager
microsoftwindows_me
microsoftwindows_2000
nortelip_softphone_2050
microsoftwindows_2003_serverr2, enterprise_64-bit, r2
microsoftwindows_xp

Timeline

  • Dec 15, 2004 CVE Published
  • Feb 4, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›